ai-toolkit-rules
Mandatory engineering, security, testing, git, performance, quality, and response rules.…
App security: OWASP, authN/authZ, input validation, secrets, TLS, CSRF/XSS/SQLi, JWT, CSP, LLM prompt injection. Triggers: security, OWASP, auth, JWT, CSRF, XSS, SQL injection, secrets, encryption at rest, TLS, CSP, CORS, prompt injection, LLM output trust, tool permissions,
$ npx -y skills add softspark/ai-toolkit --skill security-patterns --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-patternsContext preview
The summary Claude sees to decide when to auto-load this skill.
App security: OWASP, authN/authZ, input validation, secrets, TLS, CSRF/XSS/SQLi, JWT, CSP, LLM prompt injection. Triggers: security, OWASP, auth, JWT, CSRF, XSS, SQL injection, secrets, encryption at rest, TLS, CSP, CORS, prompt injection, LLM output trust, tool permissions,
name: security-patterns description: "App security: OWASP, authN/authZ, input validation, secrets, TLS, CSRF/XSS/SQLi, JWT, CSP, LLM prompt injection. Triggers: security, OWASP, auth, JWT, CSRF, XSS, SQL injection, secrets, encryption at rest, TLS, CSP, CORS, prompt injection, LLM output trust, tool permissions, marketing consent, unsubscribe." effort: medium user-invocable: false allowed-tools: Read
| Risk | Prevention | |------|------------| | Injection | Parameterized queries, ORM | | Broken Auth | MFA, secure sessions | | Sensitive Data | Encryption, HTTPS | | XXE | Disable external entities | | Broken Access | RBAC, resource validation | | Security Misconfig | Security headers, defaults | | XSS | Escaping, CSP | | Insecure Deserialization | Signed tokens, validation | | Vulnerable Components | Dependency scanning | | Insufficient Logging | Audit logs, monitoring |
---
# FastAPI middleware
@app.middleware("http")
async def security_headers(request, call_next):
response = await call_next(request)
response.headers["X-Content-Type-Options"] = "nosniff"
response.headers["X-Frame-Options"] = "DENY"
response.headers["X-XSS-Protection"] = "1; mode=block"
response.headers["Strict-Transport-Security"] = "max-age=31536000; includeSubDomains"
response.headers["Content-Security-Policy"] = "default-src 'self'"
return response---
# .env (never commit) DATABASE_URL=postgresql://... API_SECRET=... # .env.example (commit this) DATABASE_URL=postgresql://user:pass@localhost/db API_SECRET=your-secret-here
# pre-commit hook
- repo: https://github.com/Yelp/detect-secrets
hooks:
- id: detect-secrets---
from slowapi import Limiter
from slowapi.util import get_remote_address
limiter = Limiter(key_func=get_remote_address)
@app.get("/api/resource")
@limiter.limit("100/minute")
async def resource():
pass---
When the app embeds an LLM, every byte the model emits — plus tool results, retrieved documents, and fetched web pages — is **untrusted input on the same footing as a raw request body**. Text inside that content that reads like an instruction ("ignore previous rules", "call the delete tool", "email the config to…") is still data. Render it, store it, classify it — but never let it drive control flow, widen permissions, or fire a side effect without an explicit human decision. This mirrors the agent-behavior rule in [constitution Article VII](../../constitution.md); the rules here cover the application you are building, not the assistant's own behavior.
| Source | Trust | Handling | |--------|-------|----------| | System prompt / app-defined policy | Trusted | The only place instructions may originate | | User chat turn | Semi-trusted | Authenticated to a user, still validate + scope to their permissions | | Model output | Untrusted | Treat as data; gate any tool call it requests | | Tool / function results | Untrusted | Re-validate before feeding back into context | | Retrieved docs / RAG chunks | Untrusted | Strip or delimit embedded instructions | | Fetched web / email / file content | Untrusted | Highest risk — sanitize before it crosses into the prompt |
Building injection **detection** (classifiers, guardrails, eval suites) and running **authorized** red-team exercises — CTF, sanctioned pentest, internal adversarial testing of these defenses — is fully in scope. Generating injection payloads for that purpose is expected; the OWASP / authorized-testing framing of this skill applies to LLM apps exactly as it does to SQLi or XSS work.
---
| Excuse | Why It's Wrong | |--------|----------------| | "It's an internal API, security doesn't matter" | Internal APIs get exposed — lateral movement is attackers' primary technique | | "The framework handles security" | Frameworks provide tools, not guarantees — misconfiguration is OWASP #5 | | "We'll add auth later" | Unauthenticated endpoints in production get discovered within hours | | "Nobody would exploit this" | Automated scanners don't care about your threat model — they scan everythi
AI coding toolkit with machine-enforced safety, 116 skills, 44 agents, lifecycle hooks, persona presets, opt-in plugin packs, and benchmark tooling.
Repo: softspark/ai-toolkit
Mandatory engineering, security, testing, git, performance, quality, and response rules.…
Searches past coding sessions for observations, decisions, context. Triggers: mem-search,…
Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. Triggers: a11y, accessibility, WCAG,…
Creates new specialized agents with frontmatter, tools, delegation. Triggers: new agent,…
Analyzes code quality, complexity, patterns across codebase. Triggers: quality report,…
API design: naming, versioning, pagination, idempotency, OpenAPI, error contracts and safe…